In order to curb malware and scam attacks on mobile
platforms it is important to understand how they reach the
user. In this paper, we explored the app-web interface, wherein a user may go from an application to a Web destination via
advertisements or web links embedded in the application.
We
used our implemented system for a period of two months to
study over 600,000 applications in two continents and identified
several malware and scam campaigns propagating through
both advertisements and web links in applications.
With the
provenance gathered, it was possible to identify the responsible
parties (such as ad networks and application developers).